Shai-hulud 2.0 Variant Threatens Cloud Ecosystem
ID: 949fdd23-c1a5-566c-9dca-91d9a342058b
STIX ID: report--949fdd23-c1a5-566c-9dca-91d9a342058b
Feed Name: Dark Reading
Date Published: 2025-12-01
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers detail Shai-hulud 2.0, a wormable supply‑chain malware that compromises npm developer accounts via phishing, backdoors and repackages maintained packages, leverages GitHub access to propagate, harvests secrets using tools like TruffleHog, steals cloud credentials from AWS/GCP/Azure (including secrets manager and Azure Pod Identity), and includes destructive wiper functionality; the report includes IoCs and mitigation recommendations such as least-privilege tokens, CI/CD permission restrictions, dependency pinning, and visibility into package usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
